nerdexam
EC-Council

312-50V13 · Question #259

Johnson, an attacker, performed online research for the contact details of reputed cybersecurity firms. He found the contact number of sibertech.org and dialed the number, claiming himself to…

The correct answer is A. Quid pro quo. Explanation Option A (Quid pro quo) is correct because this attack involves an exchange where Johnson offers a "service" (technical support/warning about a server compromise) in return for the victim's compliance (executing commands and installing malicious files) - a classic…

Submitted by devops_kid· Mar 6, 2026Social Engineering

Question

Johnson, an attacker, performed online research for the contact details of reputed cybersecurity firms. He found the contact number of sibertech.org and dialed the number, claiming himself to represent a technical support team from a vendor. He warned that a specific server is about to be compromised and requested sibertech.org to follow the provided instructions. Consequently, he prompted the victim to execute unusual commands and install malicious files, which were then used to collect and pass critical Information to Johnson's machine. What is the social engineering technique Steve employed in the above scenario?

Options

  • AQuid pro quo
  • BDiversion theft
  • CElicitation
  • DPhishing

How the community answered

(31 responses)
  • A
    84% (26)
  • B
    3% (1)
  • C
    10% (3)
  • D
    3% (1)

Explanation

Explanation

Option A (Quid pro quo) is correct because this attack involves an exchange where Johnson offers a "service" (technical support/warning about a server compromise) in return for the victim's compliance (executing commands and installing malicious files) - a classic "something for something" social engineering trade-off where the attacker poses as a helpful technical resource to gain access.

Why the distractors are wrong:

  • B (Diversion theft) involves tricking a courier or delivery person into delivering goods to the wrong location - it's physically oriented and doesn't match this scenario.
  • C (Elicitation) is about subtly extracting information through casual conversation without raising suspicion, not impersonating support staff to issue instructions.
  • D (Phishing) is conducted via email or fake websites, not through phone calls (phone-based attacks are specifically "vishing," a subset distinct from phishing).

Memory Tip

Think of quid pro quo as "I'll scratch your back if you scratch mine" - the attacker always offers something (help, support, a warning) in exchange for compliance or access. If the scenario involves a fake service offer over the phone leading to a trade-off action, think quid pro quo.

Topics

#Social Engineering#Quid pro quo#Vishing#Impersonation

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice